logo

Hackers target bank clients in Czechia, Hungary and Georgia in novel phishing campaign

ID: fbc72e42-e27a-54cf-8d5f-089f61d8353b

STIX ID: report--fbc72e42-e27a-54cf-8d5f-089f61d8353b

Feed Name: The Record from Recorded Future News

Threat Score
65/100

Date Published: 2024-08-20

Date Updated: 2026-05-01

...
...

Security researchers at ESET uncovered a cross-platform phishing campaign (starting November of last year) that lured victims into installing malicious progressive web applications (PWAs) impersonating legitimate European banking apps. Delivered via third-party websites and social engineering (automated calls, SMS, and social ads), the PWAs bypassed app store protections, requested installation as home-screen apps, and captured banking credentials and other sensitive data (and could access device sensors). Victims included banks in the Czech Republic, Hungary (OTP Bank), and Georgia (TBC Bank); ESET coordinated takedowns and reported findings to affected banks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.